Free scan, no account
What has your team already put on the open internet?
Someone in operations built a tool in an afternoon, it worked, and people started using it. It is still running on a public address with the customer list inside. This scan finds those, using nothing but information that is already public.
What the scan does
- Searches public web results for apps published on the platforms below.
- Looks up your public DNS records and certificate transparency logs for subdomains pointing at those platforms.
- Reads your own public website for links to them.
- Opens each candidate page once, the way any visitor would, and records the address, the page title and the platform fingerprint.
What it does not do
- No logging in. The scan never enters a password, never uses a cookie or an API key, and never follows a redirect into a login page.
- No probing. It does not guess file names, try admin paths, or look for a way in.
- No content. Page text, screenshots and anything that looks like personal data are never stored.
- No pressure to prove anything to see the numbers, and no addresses handed to anyone who has not proved they work at the company being scanned.
What you get
- A summary at a private link straight away: how many apps were found and which platforms they are on, with the date each one first appeared.
- If your address is at the domain you entered, a link to the full report goes to your mailbox: every address found, the risk score and the reasons written out. Opening that link is what proves the mailbox is yours.
- Scanning a company you do not work at is fine. You see the summary, and you can send the full report to someone there. The addresses go to them, not to you.
- Anything wrong gets one click to dismiss, so the list you keep is a list you trust.
- Links work for 14 days. Findings from a scan without an account are deleted after 30 days.
Platforms the scan covers
The AI app builders
- Lovable
lovable.appApps built by describing them in chat, published on a lovable.app address. - Bolt
bolt.hostSame idea as Lovable, published on a bolt.host address. - Replit
replit.app, repl.coOlder accounts still sit on repl.co, newer ones on replit.app. - Base44
base44.appInternal tools and simple databases, published on a base44.app address. - Emergent
emergentagent.comNewer agent builder, added as it picks up traction. - Create.xyz
created.appNewer agent builder, added as it picks up traction. - Rork
rork.appNewer agent builder, added as it picks up traction.
Where exported projects get deployed
- Vercel
vercel.app, v0.appWhere an exported Lovable or Bolt project usually ends up. Also catches v0 output. - Netlify
netlify.appThe other common home for an exported project.
The no-code layer that came before
- Bubble
bubbleapps.ioThe no-code layer that came before the AI builders. Plenty of it is still running. - Softr
softr.appPortals and client dashboards built on top of a spreadsheet or Airtable base. - Glide
glide.pageApps built from a spreadsheet, often shared on a public link.
Deliberately not scanned
Framer, Webflow, Squarespace, Carrd. Those build websites, not tools. Your marketing site being on a public address is the point of a marketing site, and reporting it as a risk would waste your time.